Sites Covered by the DC Locator DNS SRV RecordsID: oval:org.secpod.oval:def:19547 | Date: (C)2014-05-29 (M)2023-07-04 |
Class: COMPLIANCE | Family: windows |
The Sites Covered by the DC Locator DNS SRV Records machine setting should be configured correctly.
Specifies the sites for which the domain controllers (DC) register the site-specific DC Locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the DC resides, and records registered by a DC configured to register DC Locator DNS SRV records for those sites without a DC that are closest to it. The DC Locator DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication. To specify the sites covered by the DC Locator DNS SRV records, click Enabled, and then enter the sites names in a space-delimited format. If this setting is not configured, it is not applied to any DCs, and DCs use their local configuration.
Fix:
(1) GPO: Computer Configuration\Administrative Templates\System\Net Logon\DC Locator DNS Records\Sites Covered by the DC Locator DNS SRV Records
(2) KEY: HKLM\Software\Policies\Microsoft\Netlogon\Parameters\SiteCoverage
Platform: |
Microsoft Windows Server 2008 R2 |